S 6.37 Documentation of the data backup
Initiation responsibility: IT Security Officer
Implementation responsibility: Person responsible for the data backup
Within the framework of a data backup policy, it must be defined how the data backup must be documented. Documentation is necessary for a proper and functional data backup. The following must be documented for each IT system when creating the data backup:
- the date the data was backed up,
- the extent of the data backup (which files/directory were backed up),
- the data medium the data is stored to during operation,
- the data medium the data was backed up to,
- the hardware and software used for data backup (including version number), and
- the parameters selected for data backup (type of data backup, etc.).
Furthermore, the procedure used for restoring the backed up data must be described. A description of the required hardware and software, of the required parameters, and of the approach according to which the data must be restored must be created here as well.
Review questions:
- Is the approach for creating data backups and for restoring the backed up data documented sufficiently?